CVE-2008-1275 |
|
发布时间 :2008-03-10 19:44:00 | ||
修订时间 :2011-03-07 22:06:26 | ||||
NMCO |
[原文]Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edition 3.x and earlier allow remote attackers to cause a denial of service (crash) via crafted (1) EXPN or (2) VRFY commands.
[CNNVD]MailEnable SMTP服务 拒绝服务漏洞(CNNVD-200803-152)
MailEnable是一款商业性质的POP3和SMTP服务器。
MailEnable 的SMTP服务存在的多个未明漏洞。远程攻击者可以通过精心设计的(1)EXPN 或者(2)VRFY命令来造成一个拒绝服务(崩溃)。
–
CVSS (基础分值)
CVSS分值: | 7.8 | [严重(HIGH)] |
机密性影响: | NONE | [对系统的机密性无影响] |
完整性影响: | NONE | [不会对系统完整性产生影响] |
可用性影响: | COMPLETE | [可能导致系统完全宕机] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | NETWORK | [攻击者不需要获取内网访问权或本地访问权] |
身份认证: | NONE | [漏洞利用无需身份认证] |
–
CPE (受影响的平台与产品)
cpe:/a:mailenable:mailenable_standard | |
cpe:/a:mailenable:mailenable_professional:3.0 | |
cpe:/a:mailenable:mailenable_enterprise:3.0 |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
http://www.securityfocus.com/bid/28154 (PATCH) BID 28154 |
http://www.mailenable.com/hotfix/ (PATCH) CONFIRM http://www.mailenable.com/hotfix/ |
http://secunia.com/advisories/29300 (VENDOR_ADVISORY) SECUNIA 29300 |
http://www.vupen.com/english/advisories/2008/0800/references (UNKNOWN) VUPEN ADV-2008-0800 |
http://xforce.iss.net/xforce/xfdb/41083 (UNKNOWN) XF mailenable-expn-vrfy-dos(41083) |
http://www.milw0rm.com/exploits/5235 (UNKNOWN) MILW0RM 5235 |
–
漏洞信息
MailEnable SMTP服务 拒绝服务漏洞 | |
高危 | 设计错误 |
2008-03-10 00:00:00 | 2008-09-05 00:00:00 |
远程 | |
MailEnable是一款商业性质的POP3和SMTP服务器。 MailEnable 的SMTP服务存在的多个未明漏洞。远程攻击者可以通过精心设计的(1)EXPN 或者(2)VRFY命令来造成一个拒绝服务(崩溃)。 |
–
公告与补丁
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: The vendor has released a fix to address this issue. MailEnable MailEnable Enterprise Edition 2.35 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 3.13 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.83 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 2.1 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 2.0 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 1.2 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 1.40 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.72 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 2.32 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.82 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 3.13 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 2.2 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 2.35 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 1.30 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 1.41 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 1.42 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable 1.96 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 1.21 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 2.34 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 2.32 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.73 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 2.1 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 2.33 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 2.34 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 2.351 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable 1.91 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterprise Edition 0 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.84 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.0 010 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.0 016 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.0 011 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.0 006 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.0 012 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Professional 1.0 017 MailEnable ME-10039.EXE http://www.mailenable.com/hotfix/ME-10039.EXE MailEnable MailEnable Enterpris |
–
漏洞信息
42733 |
|
MailEnable SMTP Service EXPN/VRFY Unspecified DoS | |
Denial of Service |
|
Loss of Availability | |
–
漏洞描述
–
时间线
2008-03-09 |
Unknow |
Unknow | Unknow |
–
解决方案
Currently, there are no known workarounds or upgrades to correct this issue. However, MailEnable has released a patch (ME-10039) to address this vulnerability. |
–
相关参考
|
–
漏洞作者
Unknown or Incomplete |